nCircle.com >> nCircle Blog >> Sync

« 5 Reasons Why the iPhone 2.0 is still not Enterprise 1.0 Ready | Main | Apple DNS Patch Fails To Randomize - Users Still At Risk »

San Francisco IT Admin Charged with Hijacking the City's Network.

Link to PC World Article


Link here

Being an IT manager and security professional, this story make me shake my head. It has certainly been the talk soup at the office today. A few quick thoughts on this.

Terry Childs seems to have backed himself into a corner and created a no-win situation. He had to have been in a desperate position to take the system hostage by blocking access and refusing to hand over passwords. Unfortunately for Childs, real life computer security rarely works like it does in the movies, bargaining power is limited by the long arm of the law.

Child's managers should have known better. A situation like this could only occur if safety nets and best practices were ignored or circumvented. Any security program that could allow one person to cause much damage is seriously deficient, especially since this has apparently been going on since June 20th.

The big question in my mind concerns the ramifications of continuing to run a system that could have been rigged to remotely delete data. If this concern turns out to be accurate, every minute that the city keeps the system up while it is not entirely in their control is another minute that city data is in jeopardy. A compromised system could mean data is deleted and confidential information gets leaked. Both of these are a significant risks.


Update:
Linked to the Robert McMillan article in PC World since he used my quote.

TrackBack

TrackBack URL for this entry:
http://blog.ncircle.com/cgi-bin/mt-tb.cgi/287

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Verification (needed to reduce spam):

Bio

Blog: Sync
Author: Andrew Storms

As nCircle's Director of Security Operations, Andrew Storms is responsible for setting and enforcing the company's security compliance programs as well as overseeing day-to-day operations for the Information Technology department. He is a Certified Information Systems Security Professional (CISSP).

About

This page contains a single entry from the blog posted on July 15, 2008 3:37 PM.

The previous post in this blog was 5 Reasons Why the iPhone 2.0 is still not Enterprise 1.0 Ready.

The next post in this blog is Apple DNS Patch Fails To Randomize - Users Still At Risk.

Many more can be found on the main index page or by looking through the archives.